Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion Chain — Threadlinqs Intelligence
As of 2026-07-19, Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion Chain is a high-severity malware threat attributed to Shamel (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1533 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Shamel · Russia · FINANCIAL
Lumma Stealer (LummaC2) is a Russian-developed, subscription-based Malware-as-a-Service infostealer active since August 2022 that ranked #1 in ANY.RUN's malware detection statistics as of September
Lumma Stealer, tracked by the security community as LummaC2, first appeared for sale on Russian-language cybercriminal forums in 2022 and is attributed to a threat actor operating under the alias "Shamel." It is offered as a tiered Malware-as-a-Service subscription (documented pricing from roughly $140/month for a standard build up to $20,000 for a source-code license enabling resale), marketed and supported through Telegram channels with 1,800+ members.
The malware's most recent documented distribution chain (Genians, October 2025) begins with phishing sites disguised as pirated/cracked software. Victims are redirected through multiple intermediary sites to obscure the origin, with the final payload staged on MEGA cloud storage. The downloaded Setup.exe is an NSIS (Nullsoft Scriptable Install System) installer that drops files into %Temp%, opens a decoy document ("Contribute.docx") to distract the victim, and invokes the native Windows utility extrac32.exe to extract a CAB archive disguised as "Make.docx," which actually contains 11 component files including a fragmented, ASCII-obfuscated AutoIt3.exe runtime and a heavily obfuscated compiled AutoIt script full of dummy/junk code. The AutoIt script reassembles the fragmented interpreter, decrypts embedded shellcode, and performs process hollowing/injection into a process that displays as an innocuous file named "Riding.pif" while actually executing the Lumma payload in memory — evading static and process-name-based detections. Before execution, the malware enumerates running processes to detect and evade security products including Sophos, Norton, ESET, and Bitdefender.
Lumma is written in C++ and assembly and targets Chromium-, Mozilla-, and Gecko-based browsers, harvesting session cookies, autofill data, saved passwords, cryptocurrency wallet keys/extensions, Telegram session data, email/FTP/VPN/RDP client credentials, and user documents. Exfiltration occurs over HTTP POST to attacker C2 infrastructure that fronts real backend servers behind proxy layers; C2-delivered configuration files control which browsers/wallets/apps are targeted per victim.
Beyond the phishing/cracked-software vector, Lumma affiliates independently distribute the stealer via malvertising (poisoned search results impersonating legitimate brands), compromised websites injecting malicious JavaScript, GitHub repository social-engineering campaigns (fake tool/cheat repos), and — most prominently — ClickFix / fake-CAPTCHA social engineering, where victims are instructed to press Win+R and paste an attacker-supplied command that downloads and runs the stealer via PowerShell, mshta, or a non-resident EXE/DLL loader.
In May 2025, the FBI and CISA issued joint advisory AA25-141B documenting LummaC2 TTPs and IOCs spanning infections from November 2023 through May 2025, coinciding with a coordinated takedown led by Microsoft's Digital Crimes Unit alongside the US DOJ, Europol, and Japan's Cybercrime Control Center that disrupted approximately 2,300 malicious domains (1,300+ seized or transferred to Microsoft) and targeted the central command-and-control panel infrastructure. LummaC2 operators publicly acknowledged the disruption to their Telegram customer base and stood up replacement domains within 24-48 hours; the government seized those replacement domains as well within days, but the operation ultimately only delayed rather than eliminated the service, and Lumma resumed high-volume operation within weeks.
Most recently, Microsoft Threat Intelligence disclosed (March 5, 2026) a new ClickFix variant observed in campaigns from February 2026 that abandons the traditional Win+R Run-dialog lure — which many EDR products now alert on via process-parentage rules — in favor of instructing victims to open Windows Terminal directly (Win+X, then "I"). This blends malicious command execution into what appears to be a legitimate administrative workflow and defeats detection logic keyed to Run-dialog ancestry. The Wind
Target sectors: technology, finance, criticalinfrastructure, gaming, education, cryptocurrency, generalenterprise
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1189, T1204, T1059, T1059, T1106, T1218, T1053, T1055